Privacy Policy
Last updated: May 23, 2026
We collect minimal data to deliver a personalized news experience. We use your email for newsletters, Google profile for authentication, and privacy-first analytics. We do not sell your personal data. You have rights under GDPR, CCPA, and Taiwan's PDPA.
1. Who We Are
Connact Inc. (康耐德股份有限公司) operates the Seges Intelligence platform at news.seges.ai. For privacy inquiries, contact contact@seges.ai.
2. Information We Collect
Information you provide
- Email address (newsletter subscription, account registration)
- Google account information (name, email, profile picture) via Google OAuth
- Newsletter preferences (language, digest frequency, delivery channel)
- Interest and topic preferences
- Article ratings and feedback
- Unsubscribe reasons (optional)
Information collected automatically
- Pages visited, referrer URL, browser type (user agent)
- Preferred language and locale
- Timezone (for newsletter delivery optimization)
- Timestamps of visits and interactions
- IP address (processed but not stored in identifiable form)
Information we do NOT collect
- No third-party tracking cookies
- No advertising pixels or cross-site trackers
- No financial or payment information collected
- No third-party adtech platforms
We run our own first-party product analytics (via the /api/analytics endpoint on our own domain) that records the page path you view, the referring URL, and your browser type (user agent), so we can understand how the Service is used and improve it. This data is first-party and self-hosted on Google Cloud; it is not shared with any third-party adtech platform and is not used for cross-site tracking. We do not use Plausible or any third-party analytics service.
3. How We Use Your Information
- Deliver personalized news and newsletter content
- Authenticate your account and maintain session security
- Send newsletters and content notifications based on your preferences
- Ensure Service security and prevent abuse
- Comply with legal obligations
- Communicate important service updates
First-party product analytics (necessary to operate the Service)
To operate, secure and improve the Service, we record basic usage data with our own first-party product analytics (page path, referrer and browser type — see Section 2 above). This is internal operational telemetry: first-party, self-hosted, never shared with a third-party adtech platform, never used for cross-site tracking, and never used to serve advertising. We do not sell this data.
In countries that do not recognise “legitimate interest” as a lawful basis (including China, India, Vietnam, Malaysia and Hong Kong — see Section 13), this product analytics runs only on your consent or on irreversibly de-identified data.
Purposes that require your separate consent
The following purpose is not necessary to deliver the service you asked for, so we will not use your personal data for it unless you give us separate, specific consent that you can withdraw at any time. You may decline or withdraw it without affecting your use of the Service:
- Training and improving our AI and machine-learning models — we tell you plainly when this is the purpose, and we never train on special-category (sensitive) data
Separately, we may create irreversibly de-identified or aggregated data that can no longer be linked to you; such data is no longer personal data and we may use it freely (including for analytics and model training).
4. Legal Bases for Processing
- Contract performance: account registration, newsletter delivery
- Consent: newsletter subscription, interest personalization, optional communications, and AI / model training (a separate, withdrawable consent — see Section 3 above)
- Legitimate interests: to operate and protect the Service (security, abuse and fraud prevention, basic service operation) and to run first-party product analytics to understand and improve the Service (see Section 3). We do not rely on this basis in countries that do not recognise it (see Section 13), where that product analytics runs only on your consent or on irreversibly de-identified data. We do NOT rely on legitimate interests for AI / model training — that runs only on your consent or on irreversibly de-identified data.
- Legal obligation: compliance with applicable laws
5. Data Sharing
- Service providers: cloud infrastructure (Google Cloud Platform), email delivery services — processing data on our behalf under strict contractual obligations
- Legal requirements: when required by law, regulation, legal process, or governmental request
- Business transfers: in connection with a merger, acquisition, or sale of assets, with prior notice
- Aggregated data: we may share anonymized, aggregated analytics that cannot identify you
We do NOT sell your personal data to third parties.
6. International Data Transfers
We host our services on Google Cloud Platform. By default, personal data of users in Taiwan and the wider region is processed in Google Cloud's Taiwan region (asia-east1) — it stays on-shore. We do NOT route or transfer personal data through mainland China, Hong Kong, or Macau.
When data is processed outside your country, we put a lawful transfer mechanism in place — a data-processing agreement with our providers plus standard contractual clauses or the equivalent your law requires. For personal data of people in the EU/EEA and UK, we keep that data in European regions and use the European Commission's standard contractual clauses (or the UK IDTA) together with a transfer-risk assessment (Schrems II). The specific mechanism for your region is described in Section 13 below.
7. Data Retention
- Account data: retained while active, plus 30 days after deletion request
- Newsletter subscription: retained until you unsubscribe
- Product analytics data: page-view logs from our first-party product analytics contain the page path, referrer and browser type (we do not store IP addresses in identifiable form). We commit to capping retention of the raw page-view logs at 90 days, after which they are purged; aggregated or irreversibly de-identified statistics may be kept indefinitely.
- Security logs: retained for up to 12 months
8. Data Security
We implement industry-standard security measures including encrypted connections (TLS), secure authentication (JWT with httpOnly cookies), access controls, and regular security audits. However, no method of transmission or storage is 100% secure.
If a personal-data breach occurs, we will notify the relevant regulator and affected individuals within the strictest timeline that applies to us — in most cases within 72 hours of becoming aware — and we keep an internal breach register.
9. Your Rights
European Economic Area (GDPR)
You have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. You may withdraw consent at any time.
California Residents (CCPA/CPRA)
You have the right to know what personal information we collect, request deletion, opt out of the sale of personal information (we do not sell your data), and not be discriminated against for exercising your rights.
Taiwan Residents (PDPA)
Under the Personal Data Protection Act (個人資料保護法), you have the right to request access, copies, supplementation, correction, cessation of collection/processing/use, and deletion of your personal data.
To exercise any of these rights, contact contact@seges.ai. We will respond within 30 days.
10. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal information from children under 16. If we learn we have collected such information, we will promptly delete it.
11. Changes to This Policy
We may update this Policy periodically. Material changes will be communicated via the Service or email. Your continued use after changes constitutes acceptance.
12. Contact
Data Protection Contact: contact@seges.ai
Connact Inc. (康耐德股份有限公司)
13. Your Region
We process your data to one high standard — the strictest of the laws that apply to us — and add the region-specific terms your country requires below. Where your law requires a local representative or contact point, ask us and we will provide their current details.
Taiwan & Hong Kong
Your data is processed in Google Cloud's Taiwan region (asia-east1) by default and is not transferred to mainland China, Hong Kong, or Macau. We comply with Taiwan's Personal Data Protection Act (and Hong Kong's PDPO where it applies), including its notice, consent, and breach-reporting duties.
European Union / EEA & United Kingdom
We comply with the GDPR and UK GDPR. Taiwan is not an EU-adequate country: personal data of people in the EU/EEA and UK is kept in European regions, and international transfers use the European Commission's standard contractual clauses (or the UK IDTA) with a transfer-risk assessment (Schrems II). We will name our EU Article 27 representative on request, and the newsletter is opt-in under the ePrivacy Directive. You may lodge a complaint with your national supervisory authority and have the right not to be subject to solely-automated decisions that significantly affect you.
California & the United States
We give the notice required by the CCPA/CPRA. We do not sell your personal information or share it for cross-context behavioural advertising; we honour the Global Privacy Control browser signal and any “Do Not Sell or Share” request.
China, India, Vietnam, Malaysia & Hong Kong (no legitimate interest)
In these countries we do not rely on “legitimate interest” as a basis for processing. First-party product analytics and AI / model-training reuse therefore run ONLY on your explicit, named-purpose consent or on irreversibly de-identified data. In India, we give a standalone, itemised notice and support a registered Consent Manager where the law requires it.
Indonesia, Vietnam & Thailand
We provide this policy in the local language (Bahasa Indonesia, Tiếng Việt, Thai) where the law requires it, and put the required cross-border-transfer mechanism in place before processing your data — including Vietnam's filed transfer-impact assessment (TIA) and Indonesia's Electronic System Operator (PSE) registration acknowledgement under UU PDP. In these countries we do not rely on legitimate interest for analytics or AI / model training; those run only on your consent or on irreversibly de-identified data.
Nigeria, Kenya & South Africa
We comply with the Nigeria Data Protection Act (NDPA), Kenya's Data Protection Act and South Africa's POPIA respectively, name the relevant regulator (Nigeria's NDPC, Kenya's ODPC, South Africa's Information Regulator), register where the law requires it, and use the approved cross-border-transfer mechanism (in Nigeria including the NDPC's cross-border data-transfer — CBDTI — approval).